Vulnerability index

Browse CVEs

1,344 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Unclassified MEDIUM 6.0
CVE-2025-0309

An insufficient validation on the server connection endpoint in Netskope Client allows local users to elevate privileges on the system. The insuffici…

Mitigation only
Fix from $1,600 2025-08-14
Unclassified MEDIUM 5.3
CVE-2025-2183

An insufficient certificate validation issue in the Palo Alto Networks GlobalProtect™ app enables attackers to connect the GlobalProtect app to arbit…

Mitigation only
Fix from $1,600 2025-08-13
F5 Access HIGH 7.4
CVE-2025-54809

F5 Access for Android before version 3.1.2 which uses HTTPS does not verify the remote endpoint identity. Note: Software versions which have rea…

Fix: 3.1.2+
Fix from $1,950 2025-08-13
Unclassified HIGH 7.3
CVE-2025-8393

A TLS vulnerability exists in the phone application used to manage a connected device. The phone application accepts self-signed certificates when …

Mitigation only
Fix from $1,950 2025-08-08
Unclassified MEDIUM 5.4
CVE-2025-20215

A vulnerability in the meeting-join functionality of Cisco Webex Meetings could have allowed an unauthenticated, network-proximate attacker to comple…

Mitigation only
Fix from $1,600 2025-08-06
Unclassified MEDIUM 5.7
CVE-2025-48393

The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to pe…

Mitigation only
Fix from $1,600 2025-08-06
Log Server MEDIUM 5.3
CVE-2025-2028

Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs

Mitigation only
Fix from $1,600 2025-08-06
Harmonyos HIGH 7.5
CVE-2025-54607

Authentication management vulnerability in the ArkWeb module. Impact: Successful exploitation of this vulnerability may affect service confidentialit…

No fix yet
Fix from $1,950 2025-08-06
Ilx 507 Firmware HIGH 8.0
CVE-2025-8476

Alpine iLX-507 TIDAL Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on…

Mitigation only
Fix from $1,950 2025-08-01
Vault MEDIUM 6.8
CVE-2025-6037

Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certifi…

Fix: 1.16.23 / 1.18.12+
Fix from $1,600 2025-08-01
Mq Operator MEDIUM 6.5
CVE-2025-36005

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator…

Fix: after 3.6.0
Fix from $1,600 2025-07-24
Unclassified CRITICAL 9.2
CVE-2025-7395

A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in t…

Mitigation only
Fix from $2,300 2025-07-18
Device Manager MEDIUM 6.8
CVE-2025-30024

The communication protocol used between client and server had a flaw that could be leveraged to execute a man in the middle attack.

Fix: 5.32.137+
Fix from $1,600 2025-07-11
Workplace Desktop CRITICAL 9.1
CVE-2025-46788

Improper certificate validation in Zoom Workplace for Linux before version 6.4.13 may allow an unauthorized user to conduct an information disclosure…

Fix: 6.4.13+
Fix from $2,300 2025-07-10
Openshift Container Platform MEDIUM 5.3
CVE-2025-32989

A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) exten…

Mitigation only
Fix from $1,600 2025-07-10
Unclassified MEDIUM 6.5
CVE-2025-35983

Improper Certificate Validation (CWE-295) in the Controller 7000 OneLink implementation could allow an unprivileged attacker to perform a limited den…

Mitigation only
Fix from $1,600 2025-07-10
Windows 11 22h2 MEDIUM 6.5
CVE-2025-48802

Improper certificate validation in Windows SMB allows an authorized attacker to perform spoofing over a network.

Fix: 10.0.20348.3932 / 10.0.22621.5624+
Fix from $1,600 2025-07-08
Sicam Toolbox Ii HIGH 8.1
CVE-2024-31854

A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS server of a ma…

Fix: 07.11+
Fix from $1,950 2025-07-08
Sicam Toolbox Ii HIGH 8.1
CVE-2024-31853

A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS server of a ma…

Fix: 07.11+
Fix from $1,950 2025-07-08
Internet Security MEDIUM 6.1
CVE-2025-7095

A vulnerability classified as critical has been found in Comodo Internet Security Premium 12.3.4.8162. This affects an unknown part of the component …

No fix yet
Fix from $1,600 2025-07-06
Unclassified HIGH 8.3
CVE-2025-34066

An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with --no-check-certificate in sc…

No fix yet
Fix from $1,950 2025-07-01
3x Ui CRITICAL 9.8
CVE-2025-29331

An issue in MHSanaei 3x-ui before v.2.5.3 and before allows a remote attacker to execute arbitrary code via the management script x-ui passes the no …

Fix: 2.5.3+
Fix from $2,300 2025-06-26
Unclassified HIGH 8.3
CVE-2025-6032

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. …

Patch available
Fix from $1,950 2025-06-24
Firefox CRITICAL 9.8
CVE-2025-6433

If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the …

Fix: 140.0+
Fix from $2,300 2025-06-24
Microscada X Sys600 MEDIUM 6.5
CVE-2025-39205

A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol allows remote Man-in-the-Middl…

Fix: 10.7+
Fix from $1,600 2025-06-24
Coros Pace 3 Firmware CRITICAL 9.8
CVE-2025-32878

An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. This function is mainly fo…

Fix: after 3.0808.0
Fix from $2,300 2025-06-20
Mq Operator CRITICAL 9.8
CVE-2025-36041

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1 through 3.5.3, and MQ O…

Fix: after 3.5.3
Fix from $2,300 2025-06-15
Fortisase MEDIUM 6.5
CVE-2025-24471

An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remo…

Fix: 7.4.8 / 7.6.2+
Fix from $1,600 2025-06-10
File Station HIGH 8.8
CVE-2025-33031

An improper certificate validation vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then…

Fix: 5.5.6.4847+
Fix from $1,950 2025-06-06
File Station HIGH 8.8
CVE-2025-30279

An improper certificate validation vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can the…

Fix: 5.5.6.4847+
Fix from $1,950 2025-06-06